Arbitrary Command Injection in Root Browser Classic by JRummy Apps
CVE-2026-85082

8.5HIGH

Key Information:

Vendor
CVE Published:
24 September 2026

What is CVE-2026-85082?

Root Browser Classic version 3.3.0 is susceptible to an arbitrary command injection vulnerability. This occurs because the application allows the path of a selected SQLite database to be passed directly to the operating system shell without appropriate sanitization. As a result, an attacker could exploit this flaw to execute arbitrary commands, which may compromise the integrity of the device and its data.

Affected Version(s)

Root Browser Classic Android 3.3.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrés Ramos
.